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AMENDMENTS TO THE SPECIFICATION : 

Please amend the sentence on Pane 4. lints 27 -28 *ith the following: 

Figure 4 is a schematic representation of the server station of Figure 3 3^according to an 
embodiment of the invention . 



Please amend the rahte nn Pauv. 77 lines 71-27 witty the following: 



Occurrence Index: 

Total # of agents and/or 
employees 

# of policies in force 

# of policies issued 
in past 12 months 



0 1 

N/A <10,001 



10,000-100,001 



N/A <50 a 0[[,]]00 50,0[[JJQ0-2M 



N/A <50,000 



50,000-200,000 



>100,001 

>2M 
>200,Q00 



Please delete the formula on Pase 14. line 28: 

(2){3) 6 



Please add ihe following formula on Put-e 14 line 28: 

1(1) + 2(3) + 3(1) 1 5(1) 15 
Detect — = -~2.S 
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Plmr delete the formula on Page 15, tine 2:_ 

_ . 1(1) + 2(1) + 3(3) + 4(1) _ 16 
Detection- — -g-M 



Please add the following formula on Pane 15. line 2: 
- . 1(3) + 2(1) + 3(3) + 4(1) _ 1 8 _„ „ g 

Deiectl0n= (5S T 



Pteajg awewrf Pane ]5. lines 16-20 with the following 

Based on the above indices, a total risk score can then be determined for each of the 
categories, as follows: 

Product Pesign Risk Score = (2.5X2.0X&0M1Q1 = md 1M 
e-business Risk Score = (3)(3)t«0 = 18.0 
State Produci Filings = <3 ¥2.2S)( 2K1) = 4£4^5 



Please amend the sentence on Pa^e 1 6. linen 6-32 with the following 

Client stations 310 may include, for instance, a personal or laptop computer running a 
Microsoft Windows™ 95 operating system, a Windows™ 98 operating system, a Millenium™ 
operating system, a Windows NT™ operating system, a Windows™ 2000 operating system, a 
Windows XP™ operating system, a Windows CE™ operating system, a PalmOS™ operating 
system, a Unix™ operating system, a Linux™ operating system, a Solaris™ operating system, 
an OS/2 ™ operating system, a BeOS ™ operating system, a MacOS ™ operating system, a 
VAX VMS operating system, or other operating system or platform. Client stations 310 may 
include a microprocessor such as an Intel x86-based or Advanced Micro Devices x86-compatible 
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device, a Motorola 68K or PowerPC™ device, a MIPS device, Hewlett-Packard Precision fM 
device, or a Digital Equipment Corp. Alpha™ RISC processor, a microcontroller or other 
general or special purpose device operating under programmed control. Client stations 310 may 
further include an electronic memory such as a random access memory (RAM ) or electronically 
programmable read only memory (EPROM), a storage such as a hard drive, a CDROM or a 
rewritable CDROM or another magnetic, optical or other media, and other associated 
components connected over an electronic bus, as wiJl be appreciated by persons skilled in the art. 
Client stations 310 may. be equipped with an integral or connectable cathode ray tube (CRT), a 
liquid crystal display (LCD), electroluminescent display, a light emitting diode (.LED) or 
another display screen, panel or device for viewing and manipulating files, data and other 
resources, for instance using a graphical user interface (GUI) or a command tine interface (CU). 

TM 

Client ittflriotiG lo c ations 311) may also include a network-enabled appliance such as a WebTV 
unit, a radio-enabled Palm™ Pilot or similar unit, a set-top box, a networkable game-playing 
console such as a Sony™ Playstation™, Sega™ Dreamcast™ or a Microsoft™ XBox™, a 
browser-equipped or other network-enabled cellular telephone, or another TCP/IP client or other 
device. 

Please amend the sentence on Pane 19. line 25 - pape 20. l ine 18 wiih the following: 

Information stored in the database 340 may be input and administered by a representative 
of the compliance office, for example, via an administration interface 350. Information entered 
by the representative may, in one example, correspond to the specific questions that will be 
presented to the various departments or units relating to compliance matters involving various 
business areas or categories. In addition, the representative may input the various indices and 
formulas relevant to the prioritization process of the invention. For instance, the representative 
may input the corresponding occurrence and severity risk indices that may be used to weigh the 
responses of the individual departments or units. The representative may, for example, input the 
parameters of the possible answers to the questions presented, such as, "0" for N/A, V T' for Yes, 
no further work is needed, "2" for Yes, some improvement is needed to get to the level the 
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compliance office wants, "3" for No. almost to yes, "4" for No, sometimes, and "5" No, seldom 
or never. Other levels or distinctions are contemplated and possible. Likewise, the 
representative of the compliance office may input the different levels associated with the 
occurrence index, as well as the formula and levels used in determining or calculating the 
appropriate detection indices. For example, the representative may input, in relation to the 
occurrence index, that "0" corresponds to N/A, "1" to <10,001 employees (or policies), "2" to 
10.000-100,001 employees (or policies), "3" to > 100,001 employees (or policies), etc Further, 
the representative may also use administration module -»SQmnduie 350 to input identification 
information of the individual departments or units, such as, for example, the IP address 
corresponding to each department, or username and password information. The identification 
information may he used by the compliance office to personalize the survey or series of 
questions based on the identity of the receiving department or unit. Other information may he 
entered. In all instances, the inputted information may be stored and updated, as necessary. 

Please amend the sentence on Paee 2 J. lines 1-2 J with the followinz: 

The server ^rarinn s a nation 33Q may also include a query module 410 for entering, 
organizing and editing the questions to be presented to the various departments or units. By way 
of example, a representative of the compliance office may access query module 410, via 
interface 350, and specifically draft and revise the questions to be presented to the departments 
or units as part of the survey. Further, the representative may use query module 410 to 
categorize or associate individual questions with one or more business areas or categories. For 
instance, certain questions may be presented in connection with the produce design category of 
the Product Development area, while others may be presented in connection with all categories 
of Product Development. Query module 410 may thus be used to correlate the individual 
questions with corresponding business areas and categories. Similarly, query module 410 may 
also be used to co-relate questions with individual departments or units. Specifically, query 
module 410 may be used by the compliance office to designate which questions, business areas, 
or categories should be presented to which departments or units. Query module 410 may also be 
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used to automatically identify the department or unit based, in one embodiment, on the user's IP 
address. In another embodiment, the query module 410 determines the user's identity based on 
log-tn information provided by the user, such as the user's usemame and password, and accesses 
information stored in the detaba: " 40 &ia tfflSS 3JQ relating to the identified user. In either case, 
the information stored in the database *4QdJlgbasgJ3Q may be used to personalize the survey or 
series of questions presented. 



Please amend the sentences o n Pate 22. lines 1-15 with the following: 

Server 330 may also include a prioritization module 420 that serves to prioritize or rank 
the business areas or categories based on the severity risk of non-compliance. In one 
embodiment, severity risk is determined by the responses provided by the departments or units to 
the questions presented, and by a severity risk index that, in one embodiment, may be selected by 
the compliance office. In another embodiment, the prioritization module determines or 
calculates a detection index that, as discussed above, is based on the responses of the 
departments or units, the number of questions, and the number of participating departments or 
units. In another embodiment, prioritization module 420 may be used to select an occurrence 
index indicating the potential consequences of non-compliance. In yet another embodiment, the 
prioritization module may also be used to calculate a total risk score for each category for which 
questions were presented. For example, prioritization module 420 may be usefjja.calculate the 
product of the detection, occurrence, and severity risk indices. In one embodiment, the 
occurrence and severity risk indices are selected by the compliance office for each category. The 
information needed for this calculation may be obtained by prioritization module 420 by 
accessing database 340. 



Page 6 



PAGE 8123 1 RCVD AT 3/13/2006 7:54:17 PM (Eastern Standard Time] • SVfcUSPTO-EFXRMI 1 » ON1S:2738300 » CSID:+* DURATION (mn>ss):05-00 



